ISA/IEC 62443-3-2:2020, Clause 4.7 covers documenting cybersecurity requirements, assumptions and constraints as zone and conduit requirement ZCR 6.
ZCR 6 turns assessment outcomes into a usable design package: the cybersecurity requirements specification (CRS). The CRS records mandatory countermeasures from the detailed assessment plus policy, site and regulatory expectations needed to achieve each zone’s SL-T. It need not be a single standalone file — a section inside other IACS design documents can suffice if the content is there. For a catalogue of related assessment documents, see Documentation.
Reference: ISA/IEC 62443-3-2:2020, Clause 4.7
Related:
Documentation
|
Zone, Conduit and Risk Assessment (Clause 4)
|
Prepare for an Assessment
|
Threats
|
Vulnerabilities
|
ZCR 5 – Detailed Risk Assessment
|
ZCR 7 – Asset Owner Approval
|
Automation Solution Security Lifecycle
|
Zone and Conduit Security Strategy
|
Conceptual Design Specification
|
Part 3-3 Security Levels
ZCR pages: ZCR 1 | ZCR 2 | ZCR 3 | ZCR 4 | ZCR 5 | ZCR 6 | ZCR 7
If assessment steps are not documented, there is nothing to verify, audit or prove. CRS and related assessment artefacts should be revised, amended, reviewed and approved, and held under a control scheme because they contain sensitive security information. They are living documents: when a zone or the SuC changes, related records must be updated.
Review risk-assessment documentation at least once a year, and also when significant SuC or geopolitical changes occur. Typical change triggers include:
See the full catalogue on Documentation.
Reference: ISA/IEC 62443-3-2, Clause 4.7
Clause: 4.7.2
Clear documentation keeps owners, integrators and suppliers working from the same target. ISA technical reports on related CRS content can supplement — they do not replace the minimum list in Part 3-2.
In practice the CRS is often a set of controlled spreadsheets or databases rather than one monolithic file — still assign information-security classification and access control. Grouping requirements aids readability, for example:
Course materials also describe CRS content by themes such as scope and purpose of the system, physical and environmental security, general cybersecurity requirements, and zone/conduit-specific requirements — map those themes to ZCR 6.2–6.9 rather than treating them as a separate normative list.
At a minimum a CRS includes: a description of the system under consideration; zone and conduit drawings; zone and conduit characteristics; operating environment assumptions; threat environment; organisational security policies; tolerable risk; and regulatory requirements. It does not need to be a single document — spreadsheets and databases are common when controlled.
The CRS is the primary input to conceptual design and to the Develop & Implement phase of the automation solution security lifecycle. It typically carries assigned target security levels (SL-T) that design and implementation must meet (see Part 3-3 Security Levels). Downstream design teaching: Zone and Conduit Security Strategy | Conceptual Design Specification.
Clause: 4.7.3
A practical CRS checklist for the SuC description includes:
Preparation evidence on Prepare for an Assessment and the perimeter work in ZCR 1 feed this CRS section.
Clause: 4.7.4
Clause: 4.7.5
Those fields exist for design, accountability and monitoring: they mark who owns the partition, where traffic enters, what would be lost if it fails, which SL-T and policies apply, and what outside factors (power, outer networks, physical layers) the design assumes. Final security-requirement lists typically wait until the detailed assessment in ZCR 5 is complete.
Characteristics checklist (every zone and conduit):
Confirm your organisation has these characteristics documented for every zone and conduit before treating the CRS as complete for design hand-off.
Clause: 4.7.6
Clause: 4.7.7
Document threat sources, threat vectors, and the geo-political and physical environment. Cite where threat intelligence comes from — examples include:
Teaching depth on sources, capability and vectors: Threats.
Clause: 4.7.8
Clause: 4.7.9
Clause: 4.7.10